CVE-2014-3608
Openstack Nova < 2013.2.4 - Resource Management Error
Title source: ruleDescription
The VMWare driver in OpenStack Compute (Nova) before 2014.1.3 allows remote authenticated users to bypass the quota limit and cause a denial of service (resource consumption) by putting the VM into the rescue state, suspending it, which puts into an ERROR state, and then deleting the image. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-2573.
References (5)
Scores
EPSS
0.0069
EPSS Percentile
71.5%
Classification
CWE
CWE-399
Status
draft
Affected Products (2)
openstack/nova
< 2013.2.4
pypi/nova
< 2014.1.3PyPI
Timeline
Published
Oct 06, 2014
Tracked Since
Feb 18, 2026